11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

802 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> Countermeasures●Installing URLScan 2.0 without running IISLockdown: To install URLScanwithout running IISLockdown, you need to manually extract it from the IISLockdown Tool. First you need to save IISLockd.exe to a directory. Then to extractthe URLScan setup files, run the following comm<strong>and</strong> at the comm<strong>and</strong> line fromthe directory where you installed IISLockd.exe:iislockd.exe /q /c●●This unpacks URLScan.exe which is the URLScan installation program.For more information, refer to Microsoft Knowledge Base article 315522, “How To:Extract the URLScan Tool <strong>and</strong> Lockdown Template Files from the IIS LockdownTool.”Installing URLScan 2.5: URLScan 2.5 is currently the latest version of URLScan. Ifyou want to install URLScan 2.5, you first need URLScan 1.0 or URLScan 2.0.For more information, refer to Microsoft Knowledge Base article 307608, “INFO:Availability of URLScan Version 2.5 <strong>Security</strong> Tool.”Default installation directory: The URLScan files including Urlscan.dll,URLScan.ini <strong>and</strong> URLScan logs are stored in%windir%\system32\inetsrv\urlscan. URLScan.dll is the filter. You useURLScan.ini to configure the way it works.Log FilesURLScan creates log files that record rejected requests. Log files are located in thefollowing folder:%windir%\system32\inetsrv\urlscanLog files are named using the following convention: URLScan.log.Removing URLScanYou remove URLScan manually by using the ISAPI filters page of the <strong>Web</strong> serverproperties dialog in Internet Services ManagerConfiguring URLScanTo configure URLScan to determine which requests should be rejected, you useURLScan.ini. This is located in the following folder:%windir%\system32\inetsrv\urlscanFor more information on how to modify the various sections in URLScan.ini, referto Microsoft Knowledge Base article 815155 “How To: Configure URLScan to ProtectASP.NET <strong>Web</strong> <strong>Application</strong>s.”

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!